Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lina Li

#47186of 53,632
5.4Total CVSS
Vulnerabilities · 1
PT-2024-20904
5.4
2024-02-22
Fuel Cms · Fuel Cms · CVE-2024-25369
**Name of the Vulnerable Software and Affected Versions** FUEL CMS version 1.5.2 **Description** A reflected Cross-Site Scripting (XSS) issue allows attackers to run arbitrary code via a crafted string after the `group id` parameter. **Recommendations** For FUEL CMS version 1.5.2, consider restricting access to the `group id` parameter to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.